LPF - HIPAA Implementation Past Issues HIPAA Implementation Newsletter
current past resources LPF home HIN home

HIPAA Implementation Newsletter Past Issues


Search LP&F Web site including HIPAA Implementation Newsletter

What is HIPAA? A good place to start.
By Issue Number
By Topic with Issue #

Issue #59 -- Friday, Jaune 6, 2003

Issue #58 -- Friday, May 23, 2003
  • Banks: Cash Flow
  • Transactions: Cash Flow
  • Transactions: Devil in Details
  • risk to the CEO
  • Status: Transactions & Hospitals
  • HIPAA Insurance
  • Privacy: The Press

    Issue #57 -- Friday, May 9, 2003

  • Costs: New Assessments
  • Security: Getting Started
  • Litigation: First HIPAA Lawsuit
  • Sanctions
  • Security: Microsoft

    Issue #56 -- Friday, April 25, 2003

  • First Issue After Privacy
  • SARS Exploitation by Computer Virus
  • Identity Theft: Visa Goes Beyond Technical Security
  • Identity Theft: Survey
  • Status: Transactions, WEDI
  • Status: Transactions and States
  • Security: Audits
  • Security: Mobile Devices
  • Security: Mobile Devices for EMS
  • Security: SPAM
  • Security: SearchSecurity HIPAA Expert Q&A

    Issue #55 -- Friday, April 11, 2003

  • Compliance: Board of Directors
  • Compliance: Trustees
  • Compliance: FTC
  • The "Duh" Factor
  • Security: Access via Goggle | Duh!
  • Security: Physicians & Data Bases | Duh!
  • Security: Gartner Issues
  • Security: "Events" increase 84% in Three Months
  • Privacy: CTO and CPO
  • Better Late Than Never | Duh!

    Issue #54 -- Friday, March 28, 2003

  • Business Associates: General
  • Business Associates: Electrical Manufacturers
  • Business Associates: FAQ Manufacturers
  • OCR Publishes Privacy Complaint Information
  • Transactions: Payers Schedules Online
  • Transactions: Access or Post Schedules Online
  • Transactions: Companion Guide
  • Identity Theft: 98% Taking Steps to Prevent
  • More PHI More Places
  • Surveys and Certification

    Issue #53 -- Friday, March 14, 2003

  • Security: Identity Theft
  • Security: Identity Theft 7,000 Patient Files
  • Security: Identity Theft by Medical Assistant
  • Security: HIPAA Law Firm Solicitation
  • Security: Notification in Case of Breech
  • Security: California SB 1386
  • Security: Payment Processing & Banks
  • Compliance: HHS says Voluntary
  • Not Just HIPAA: Clinical Information Technology
  • Internet: Pay for Online Consultations
  • Training: Cost and Scope

    Issue #52 -- Friday, February 28, 2003

  • DWT Analysis & Comments on Security Rules
  • Security Rules and Litigation
  • Privacy Litigation
  • HIPAA and States
  • Hacking-related Insurance Costs Soar

    Issue #51 -- Friday, February 14, 2003

  • Security: Final Standards
  • Transactions: Updated Final Rule
  • Transactions: CAQH and WEDI Web Site
  • Status: Winter HIPAA Survey
  • Enforcement: FY 2004 Budget
  • Internet: Kaiser Patient Records Online
  • Privacy: Chief Privacy Officers
  • Patient Records: After the Bankruptcy
  • Consultants: Certification?_

    Issue #50 -- Friday, January 31, 2003

  • Privacy: Layered Notices
  • Privacy: Acculturation Training
  • Privacy: Marketing Under HIPAA
  • Privacy: The Next 90 Days
  • Security: SQL Worm, Internet and Patches
  • Security: Master Key Copying Revealed

    Issue #49 -- Friday, January 17, 2003

  • Status: Security Regulations
  • Security: A Broader Base
  • Privacy: Healthcare and Media Relationships
  • Billing Applications: Compliance
  • Practice Management Systems: Compliance
  • Practice Management Systems: Open
  • Internet: Physician Reimbursement II
  • Internet: Physician Reimbursement II
  • Camera Phones in Locker-Rooms

    Issue #48 -- Friday, December 20, 2002

  • HHS Readying More HIPAA Rules
  • HIPAA Scofflaws Will Not Be Hunted
  • Effect of HIPAA Rules on Employers
  • OCR Guidance: Privacy Rule
  • Privacy Rule in California
  • JCAHO Bus. Assoc. Rule

    Issue #47 -- Friday, November 29, 2002

  • Commentary: Compliance Doesn't Come In a Box
  • Bus. Assoc: Compliance Date II
  • Bus. Assoc: Chain of Trust
  • Security: Federal Government
  • Privacy: Database
  • Privacy: Iowa Dead Baby II
  • Privacy: Cost Saving and Cost to Privacy
  • What HIPAA Means to Hospitals

    Issue #46 -- Friday, November 15, 2002

  • Status: Security Regulations
  • Status: Physicians
  • Status: Transaction Extension
  • Status: Fall 2002 Survey
  • Definition: Covered Entitiy
  • Privacy: Personal Data Travels Far
  • Transactions: De-Identification Software
  • Consultant Listing

    Issue #45 -- Friday, November 1, 2002 <

  • Privacy: A Special Case
  • Privacy: Compliance Officer
  • Security: Policies That Work
  • Security: Percent of IT Budget
  • Security: Top 20 Vulnerabilities
  • Security: Passwords
  • Security: Event Management
  • Security: Certification and Accreditation

    Issue #44 -- Friday, October 19, 2002

  • Status: Low Implement. High Confusion
  • Enforcement
  • FAQ About the Privacy Rule
  • Security: Employee Leaves

    Issue #43 -- Friday, October 5, 2002

  • Privacy: Culture
  • Privacy: Tools
  • Privacy: Sports
  • Security: Network Worms
  • Business Assoc: Chain of Trust
  • HIPAA and Physicians

    Issue #42 -- Friday, September 20, 2002

  • Banking and HIPAA
  • Clearinghouses and HIPAA
  • Security: NIST guidelines
  • Security: Small Org. Connected to Large Networks
  • Security: Microsoft Word
  • Wireless secure at Last?
  • Security: Managing Viruses

    Issue #41 -- Friday, September 6, 2002

  • Status: Transaction Extensions
  • Jump Start a Late Start
  • Internet: Model Guidelines
  • Internet: Payers Web Sites
  • IT Boosts Clinical Care Quality
  • PKI: Failed Promise

    Issue #40 -- Friday, August 23, 2002

  • Status: 2nd Final Privacy Rule
  • Privacy: TofC for Modifications
  • Business Assoc: Sample Contract
  • Business Assoc: Compliance Date
  • Privacy: Sanctions
  • Privacy: Iowa Dead Baby
  • Privacy: Employers
  • Privacy: Written Authorization
  • Strategy and HIPAA

    Issue #39 -- Friday, August 9, 2002

  • Security: Wireless Networks and Devices
  • Security: Wireless Lans
  • Security: Pocket PC's
  • Security: Policing Policies
  • Security: Trends in Viruses
  • Project Contingency Planning: Privacy Timelines
  • Internet: Physician Use
  • Privacy: Lighter Side

    Issue #38 -- Friday, July 26, 2002

  • HIPAA Webinar
  • Security: Delayed Again
  • Documentation
  • Project Contingency Planning
  • Project Contingency Planning: Transactions
  • Transactions: Standard vs. Web Based
  • Privacy Rule, Transactions, Applicability

    Issue #37 -- Friday, June 28, 2002

  • Status: Privacy and Security Regulations
  • Privacy: Applicability to Health Care Providers
  • Privacy: Divorce and Restrictions on Disclosure
  • Security: Developing Policies
  • Security: People, Processes Supersede Technology
  • Transactions: Vendors of Direct 837 Services
  • Transaction: Status of Requests for Extensions
  • Resources: CalHIPAA.com

    Issue #36 -- Friday, June 14, 2002

  • Security: Expense or Investment?
  • Security: Reducing Insider Attacks
  • Security: CSO and CTO?
  • Security: Tracking Progress

    Issue #35 -- Friday, May 31, 2002

  • 3 Regulations Published May 31, 2002
  • Status: Hospitals Slow to Comply
  • Security: Beware of New Technology
  • Security: Anatomy of a Hacking
  • Security: Disposal of Computers
  • Security: SAML Specification Ready for Review
  • Training: California

    Issue #34 -- Friday, May 17, 2002

  • HHS Estimated Publication Dates
  • Privacy: Training
  • Privacy: Summaries of State Laws
  • Internet: Permission Based Marketing
  • Us of email by Physicians
  • Security: Palm Pilots
  • Transactions: Permutations
  • Consulting Arms to Wave Goodbye
  • Healthcare IT Management Satisfaction

    Issue #33 -- Friday, May 3, 2002

  • Privacy: Sanctions
  • Privacy: NPRM vs. Final Rule
  • Transaction & Privacy Planning Details
  • Security: Weaknesses That are Known
  • Status: California Privacy Implementation Survey
  • Transactions: Filing for Extension
  • HIPAA Compliance Tools Donated

    Issue #32 -- Friday, April 19, 2002

  • Privacy & Transactions
  • HIMSS Vendor Survey
  • Status: Bank Survey
  • Status: Use of email by Physicians
  • Security: Instant Messaging
  • Security: Attach Trends
  • Security: Patches
  • Security in Vendor Contracts

    Issue #31 -- Friday, April 5, 2002

  • Transactions: Filing for Extension
  • Transactions and Third Party Testing
  • Privacy: Impact on Employers
  • Security: Firewall Configuration
  • Consulting Services Demand

    Issue #30 -- Friday, March 2, 2002

  • The Second Privacy Final Rule
  • Legal: Security Now
  • Legal: HIPAA Recognized by Court
  • Transactions: Testing Time
  • The Devil and the Details
  • Use of Social Security Numbers
  • One Liners [Conference]
  • Tools: COBOL HIPAA Modification
  • Tools: Security Management
  • Tools: Online Self-Assessment
  • Tools: Online Analysis & Documentation

    Issue #29 -- Friday, March 2, 2008

  • What is HIPAA?
  • Status: Pending Regulations
  • Transactions: Delays Q&A
  • Transactions: Testing! Testing!
  • Transactions: Myths & Realities
  • Privacy: California
  • Security: Hospitals Boosting Data Security
  • Security: Intrusion Detection Perspective
  • Security: Intrusion Detection 101
  • Security: The Legal Risks of Computer Pests

    Issue #28 -- Friday February 22, 2002

  • Privacy: Privacy Officer Survey
  • Privacy: Public Concern
  • Contingency Planning: Based On Values
  • Contingency Planning: Fact Sheets
  • Project Planning: Legal
  • Security: Survey of Threats
  • Security: Wireless Vulnerabilities
  • Security: Email

    Issue #27 -- Friday, February 8, 2002

  • Testing: Planning for April 2003
  • Status: IT Priorities
  • Status: Vendors and Transactions
  • Security: Biometrics
  • Security: Smart Cards Biometrics, PKI, FBI
  • Security: Eli Lilly
  • Security: Crack Passwords

    Issue #26 -- Friday, January 25, 2002

  • Transactions: Planning for October 2003
  • Security: Contingency Planning Guide
  • Security: firewalls
  • Security: OCTAVE
  • Security: Microsoft
  • It's Not Just HIPAA: A Shift to Quality

    Issue #25 -- Friday, January 11, 2002

  • Status: Transaction Delay Signed
  • Have You Talked With Your Banker?
  • Security: Are Your Patches Current?
  • 2002 Challenges
  • It's Not Just HIPAA: Homeland Defense
  • Security: Experience Is In Demand
  • National Health Information System
  • RAND: Bioterrorism Preparedness

    Issue #24 -- Friday, December 14, 2001

  • Status: Transactions Delayed
  • Biometrics: Not a Sure Thing
  • Federal IT Security
  • It's Not Just HIPAA: Medication Safety
  • It's Not Just HIPAA: Leapfrog and CPOE
  • It's Not Just HIPAA: HHS Safety Research

    Issue #23 -- Friday, November 30, 2001

  • Proposed Security Rule - Early 2002
  • Status: Payers Unsure Partners Comply
  • Status: Health Claims Processing
  • Wireless and Mobile Computing
  • Privacy: HIPAA and the Internet
  • Privacy: Files Posted on Internet
  • Security: Information is Critical

    Issue #22 -- Friday, November 16, 2001

  • Quarterly Survey: Fall 2001
  • Transaction Sequencing
  • Security & Privacy: Policies and Procedures
  • Biotech - Comdex
  • Tablet PCs - Comdex

    Issue #21 -- Friday, November 2, 2001

  • Status of Regulations
  • X12N Implementation Guides - Addenda
  • Homeland Security: The Need for HIPAA
  • Chief Privacy Officer
  • Dentists Are Also Preparing for HIPAA
  • Access to Mobile and Wireless Tools ...
  • Microsoft BizTalk Accelerator
  • It's Not Just HIPAA: Bypassing HMOs

    Issue #20 -- Friday, October 19, 2001

  • Security: Internet
  • Security: Microsoft
  • Security: Web Sites
  • Security: Web Audit
  • Security: Public Health
  • Security: Costs
  • Paper Records: Designing

    Issue #19 -- Friday, October 5, 2001

  • Transaction Mapping: The Difficult 10%
  • Transaction Mapping: Optional Data
  • Management Questions: Transaction Data
  • Topic Papers: Transactions
  • Best Practices vs. Peer Practices
  • Internet: Paperless Health Plan
  • Resources: State Government Agencies
  • Scope: Systems Remediation

    Issue #18 -- Friday September 21, 2001

  • Context: Three Levels
  • Security: Qualified People
  • Security: Risk Assessments
  • Privacy: Liability
  • Chief Privacy Officer
  • Fax: Security
  • Not Just HIPAA: Disruptive Innovations
  • Not Just HIPAA: Internet II
  • Not Just HIPAA: Reengineering II
  • Not Just HIPAA: Leapfrog

    Issue #17 -- Friday September 7, 2001

  • Project Management: People
  • Project Management: 16 Critical Practices
  • Program Management Point of View

    Issue #16 -- Friday, August 24, 2001

  • Privacy: Legislation
  • Privacy: Cases and Stories
  • Privacy: Posters
  • Security: Biometrics
  • PMO: Perspective
  • Internet: 2nd Opinions
  • Wireless
  • Info Strategy: Include Patients

    Issue #15 -- Friday, August 10, 2001

  • It's Not Just HIPAA (2)
  • Internet: Patient Comm Guidelines
  • Internet: Silicon Valley Tests
  • Internet: Patient Communication - Healinx
  • Internet: Patient Comm. - PAMFOnline
  • Internet: Physician Reimbursement
  • Privacy: Doctor Survey

    Issue #14 -- Friday, July 20, 2001

  • Code Sets: Drugs & Biologics
  • Privacy: Overview & Update
  • Privacy: Training
  • Privacy: Students
  • Security: Telecommuting
  • Security: Outsourcing
  • PDA's and the AMA
  • Tools: Transaction Test & Cert.

    Issue #13 -- Friday, July 13, 2001

  • 1st Guidance on Privacy
  • You Thought It Was Safe (Eli Lilly)
  • Security: VPN's and PC's
  • Security: Smart Cards
  • Security: Disaster Recovery Plans
  • Security: AMA and CMA and VeriSign
  • Security: ComTrust and VeriSign
  • Resources: New Web Page
  • Tools: New Web Page

    Issue #12 -- Friday, June 29, 2001

  • Internet & Healthcare
  • Popular Uses of the Internet
  • Use of the Internet by Physicians
  • Blue Cross/Shield Online
  • How to: email For Patient Communications2
  • How to: Contracts

    Issue #11 -- Friday, June 15, 2001

  • Scope: Top Ten Planning Points
  • How to: Project Plans Analogy to Y2K
  • How to: Project Plans Dates & Constraints
  • How to: Project Plans Funct. & Guidelines
  • How to: Project Plans Milestones
  • How to: Project Plans "Public" Results
  • Tools: Project Planning & Reporting

    Issue #10 -- Friday, June 1, 2001

  • Getting Started: Types of Inventories
  • Getting Started: Vendors
  • Privacy Policy: An initial Standard
  • Policies, Procedures and Training
  • Collaboration
  • Records Retention
  • Costs: Eligibility
  • Getting Started: Business Associates
  • Status: American Hospital Assn. Survey
  • Status: Medicare

    Issue #9 -- Friday, May 18, 2001
     
  • It's Not just HIPAA
  • Security: AMA and VeriSign
  • Security: MEDePass and VeriSign
  • Scope: Licensed Physicians, IT Staff, Hospital Systems
  • Scope: Regional Health Plan

    Issue #8 -- Friday, May 4, 2001
     
  • Status: Gartner
  • Employers and Employees Medical Privacy
  • Getting Started: Transaction Testing
  • Scope: Vendors

    Issue #7 -- Friday, April 20, 2001
  • Privacy: Business Administration Policy
  • Privacy: The Clock is Running
  • Flexibility and the Orchestration of Change
  • Security: Computer Crimes

    Issue #6 -- Friday, April 6, 2001
     
  • Getting Started: Transactions
  • Scope: Transactions
  • Management Questions: Transactions
  • Getting Started: Security
  • Scope: Security
  • Management Questions: Security
  • Project Management Office

    Issue #5 -- Friday, March 30, 2001
     
  • HIPAA and Y2K
  • Reopened Public Comments on Privacy
  • Public Concern About Privacy
  • Data Paparazzi
  • Gramm-Leach_Bliley, The Other Privacy Law
  • Gramm-Leach_Bliley, HIPAA and State Laws

    Issue #4 -- Friday, March 23, 2001
     
  • Project Management Office
  • Costs
  • Costs: 1998
  • Costs: 1999 Proposed Regulations
  • Costs: 2000 "Final" Regulations
  • Costs: Your Organization

    Issue #3 -- Friday, March 16,2001
     
  • Definition: Individual identifiable health information
  • Definition: Protected Health Information (PHI)
  • Getting Started: Awareness
  • Getting Started: Assessment
  • Information Strategy

    Issue #2 -- Friday, March 9, 2001
     
  • Complexity
  • Program Management Office
  • The Value in HIPAA
  • Getting Started
  • Security is NOT New

    Issue #1 -- Friday, March 2, 2001
     
  • In the Beginning - a bit of history
  • Status of Privacy and Security
  • The Need for HIPAA
  • The Role of the Implementation Newsletter
  •  
    2002 Challenges - #25
    Have You Talked With Your Banker? - #25

    Banking
    - Gramm-Leach The Other Privacy Law #5
    - Have You Talked With Your Banker? #25
    - Bank Survey - #32
    - Banking and HIPAA - #42
    - Payment Processing & Banks

    Patient Records: After the Bankruptcy #51

    Best Practices
    - ~ vs. Peer Practices - #19
    - ~ - Risky Term - #30
    - Anatomy of a Hacking - #35

    Biotech - Comdex - #22

    Biometrics
    Not a Sure Thing - #24
    Security - #27
    Smart Cards, PKI & FBI - #27
    Blue Cross/Shield Online - #12
    Budgets: IT - #23

    Business Associates
    - ~: Sample Contract - #40
    - ~: Compliance Date - #40
    - ~: Chain of Trust - #43
    - ~: Compliance Date II - #47
    - ~: Chain of Trust - #47
    - JCAHO ~. Rule - #48
    - Business Associates: General - #54
    - Business Associates: Electrical Manufacturers - #54
    - Business Associates: FAQ Manufacturers - #54


    California: Use of Social Security Numbers - #30
    Camera Phones in Locker-Rooms - #49
    Chief Privacy Officer - #21
    Clearinghouses and HIPAA - #42
    Code Sets: Drugs & Biologics - #14
    Collaboration - #10
    Commentary: Compliance Doesn't Come In a Box - #47

    Compliance
    - Compliance: HHS says Voluntary - #53
    - ~: Board of Directors - #55
    - ~: Trustees - #55
    - ~: FTC - #55

    Consultants
    Consulting Services Demand - #31
    Consultant Listing - #46
    Consultants: Certification?_ - #51

    Context: Three Levels - #18

    Contingency Planning: Based On Values - #28
    Contingency Planning: Fact Sheets - #28
    Complexity - #2

    Costs:
    - 1998 - #4
    - 1999 Proposed Regulations - #4
    - 2000 "Final" Regulations - #4
    - Your Organization - #4
    - Eligibility - #10
    - Security - #20
    - Training: Cost and Scope - #53

    Data Paparazzi - #5

    Definitions
    ~: Individually identifiable health info. - #3
    ~: Protected Health Information (PHI) - #3
    ~: Covered Entity - #46


    Dentists Are Also Preparing for HIPAA - #21
    Documentation
    The Devil and the Details - #30

    The "Duh" Factor | Duh! - #55

    EDI - Start with Vendors - #30

    Employers
    ~/Employees Medical Privacy - #8
    Privacy: Impact on ~ - #31
    Effect of HIPAA Rules on ~ - #48


    Flexibility and Orchestration of Change - #7
    Fax: Security - #18

    email
    - Use of the Internet by Physicians - #12
    - Blue Cross/Shield Online - #12
    - How to: email Patient Communications - #12
    - Security: Email - #28
    - Use of email by Physicians - #32
    - Us of email by Physicians - #34

    Enforcement/Compliance
    - Enforcement - #44
    - HIPAA Scofflaws Will Not Be Hunted - #48
    - Billing Applications: Compliance - #49
    - Practice Management Systems: Compliance - #49
    - Internet: Physician Reimbursement II - #49
    - ~: FY 2004 Budget #51


    ERP - priority is moving up - #27
    FAQ About the Privacy Rule - #44
    Security: FBI - #27

    Federal IT Security - #24

    Getting Started:
    - Square One - #2
    - Assessment - #3
    - Awareness - #3
    - Security - #6
    - Transaction Testing - #8
    - Transactions - #6
    - Types of Inventories - #10
    - Vendors - #10
    - Business Associates - #10

    Gramm-Leach
    - HIPAA and State Laws - #5
    - The Other Privacy Law - #5
    - Have You Talked With Your Banker? - #25

    Hacking-related Insurance Costs Soar - #52

    Homeland Defense/Security
    - The Need for HIPAA - #21
    - It's Not Just HIPAA: Homeland Defense - #25
    - Security: Experience Is In Demand - #25
    - National Health Information System - #25
    - RAND: Bioterrorism Preparedness - #25


    What HIPAA Means to Hospitals - #47

    How to: General
    - email For Patient Communications - #12
    - Contracts - #12

    How to: Project Plans
    - Analogy to Y2K - #11
    - Dates & Constraints - #11
    - Functions & Guidelines - #11
    - Milestones - #11
    - "Public" Results - #11

    Identity Theft
    - Security: Identity Theft - #53
    - Security: Identity Theft 7,000 Patient Files - #53
    - Security: Identity Theft by Medical Assistant - #53
    - ~: 98% Taking Steps to Prevent - #54
    - Identity Theft: Visa Goes Beyond Technical Security - #56
    - Identity Theft: Survey - #56

    Hacking-related Insurance Costs Soar - #52



    Internet
    - Multiple Uses For - #9
    - Blue Cross/Shield Online - #12
    - Internet & Healthcare - #12
    - Popular Uses of the Internet - #12
    - Use of the Internet by Physicians - #12
    - Internet: Patient Comm Guidelines - #15
    - Silicon Valley Tests - #15
    - Patient Communication - Healinx - #15
    - Patient Communications-PAMFOnline - #15
    - Physician Reimbursement - #15
    - 2nd Opinions - #16
    - Paperless Health Plan - #19
    - Privacy: HIPAA and the ~ - #23
    - Status Reduced - #23
    - Permission Based Marketing - #34
    - ~: Physician Use - #39
    - ~: Model Guidelines - #41
    - ~: Payers Web Sites - #41
    - ~: Physician Reimbursement II - #49
    - ~: Kaiser Patient Records Online #51
    - ~: Pay for Online Consultations - #53

    Info Strategy: Include Patients - #16
    In the Beginning - a bit of history - #1

    It's Not Just HIPAA
    - Additional regulations | Internet - #9
    - Organization issues | Internet - #15
    - Disruptive Innovations - #18
    - Internet II - #18
    - Reengineering II - #18
    - Leapfrog - #18
    - Bypassing HMOs - #21
    - Medication Safety - #24
    - Leapfrog and CPOE - #24
    - HHS Safety Research - #24
    - Homeland Defense - #25
    - A Shift to Quality - #26
    - ~: Clinical Information Technology - #53

    Information Strategy - #3
    Info Strategy: Include Patients - #16
    IT Boosts Clinical Care Quality - #41
    - JCAHO Bus. Assoc. Rule - #48
    Jump Start a Late Start - #41

    Legal
    Project Planning: - #28
    - Security Now - #30
    - HIPAA Recognized by Court - #30
    - Litigation: First HIPAA Lawsuit - #57

    Management
    ~ Questions: Security - #6
    ~ Questions: Transaction Data - #19
    - Consulting Arms to Wave Goodbye - #34
    - Healthcare IT ~ Satisfaction - #34

    Microsoft BizTalk Accelerator - #21
    Privacy: Healthcare and Media Relationships - #49
    One Liners [Conference] - #30
    Outsourcing: Broader Scale - #23
    Paper Records: Designing - #20
    Patient Records: After the Bankruptcy #51
    PDA's and the AMA - #14
    Practice Management Systems: Compliance - #49
    Practice Management Systems: Open - #49

    Physicians
    - Us of email by Physicians - #34
    - HIPAA and Physicians - #43


    PKI: Failed Promise - #41
    Policies, Procedures and Training - #10

    Privacy:
    - The Status of Privacy and Security - #1
    - Public Concern - #5
    - Reopened Public Comments - #5
    - Gramm-Leach: The Other Privacy Law - #5
    - Business Administration Policy - #7
    - The Clock is Running - #7
    - Policy: An Initial Standard - #10
    - Business Associates - #10
    - 1st Guidance on Privacy - #13
    - Overview & Update - #14
    - Training - #14
    - Students - #14
    - Doctor Survey - #15
    - Legislation - #16
    - Cases and Stories - #16
    - Posters - #16
    - Liability - #18
    - Chief Privacy Officer - #18
    - Chief Privacy Officer - #21
    - Policies and Procedures - #22
    - HIPAA and the Internet - #23
    - Privacy: Files Posted on Internet - #23
    - Transaction Delay/No Delay for Privacy - #24
    - ~ Officer Survey - #28
    - Public Concern - #28
    - ~: California - #29
    - The Second Privacy Final Rule - #30
    - Impact on Employers - #31
    - Privacy & Transactions - #32
    - Sanctions - #33
    - NPR vs. Final Rule - #33
    - Transaction & ~ Planning Details - #33
    - Training - #34
    - Summaries of State Laws - #34
    - Status: Privacy and Security Regulations - #37
    - Privacy: Applicability to Health Care Providers - #37
    - Divorce and Restrictions on Disclosure - #37
    - Privacy Rule, Transactions, Applicability - #38
    - Project Contingency Planning: ~ Timelines - #39
    - Privacy: Lighter Side - #39
    - ~: TofC for Modifications -#40
    - ~: Sanctions - #40
    - ~: Iowa Dead Baby - #40
    - ~: Employers - #40
    - ~: Written Authorization - #40
    - ~: Culture - #42
    - ~: Tools - #42
    - ~: Sports - #42
    - FAQ About the Privacy Rule - #44
    - ~: A Special Case - #45
    - ~: Compliance Officer - #45
    - ~: Personal Data Travels Far - #46
    - ~: Database - #47
    - ~: Iowa Dead Baby II - #47
    - ~: Cost Saving and Cost to Privacy - #47
    - OCR Guidance: ~ Rule - #48
    - ~ Rule in California - #48
    - ~: Healthcare and Media Relationships - #49
    - ~: Layered Notices - #50
    - ~: Acculturation Training - #50
    - ~: Marketing Under HIPAA - #50
    - ~: The Next 90 Days - #50
    - ~: Chief Privacy Officers #51
    - Patient Records: After the Bankruptcy #51
    - ~ Litigation - #52
    - OCR Publishes Privacy Complaint Information - #54
    - More PHI More Places - #54
    - ~: CTO and CPO - #55
    - Better Late Than Never | Duh! - #55
    - First Issue After Privacy - 56

    Project Contingency Planning
    - Project Contingency Planning - #38
    - Transactions - #38
    - Privacy Timelines - #39

    Project Management
    People - #17
    16 Critical Practices - #17
    ~ Point of View - #17

    Program Management Office
    - Reasons for - #2
    - Expanding the theme - #4
    - Management Questions - #6
    - Larger role for -#9
    - Planning & Reporting - #11
    - PMO: Perspective - #16

    Project Planning: Legal - #28
    Return on Investment 44% - #23
    Resources: State Government Agencies - #19

    Quality
    - California - #9
    - Federal - #9
    - It's Not Just HIPAA: - #26

    Records Retention - #10
    Resources: CalHIPAA.com - #37
    Role: The Implementation Newsletter -#1
    Sanctions - #57

    Scope:
    - Security - #6
    - Transactions - #6
    - Vendors - #8
    - Lic. Phys., IT Staff, Hospital Sys - #9
    - Regional Health Plan - #9
    - Scope: Top Ten Planning Points - #11
    - providers and payers - #14
    - Scope: Systems Remediation - #19

    Security:
    - NOT New - #2
    - Getting Started: - #6
    - Scope: Security - #6
    - Management Questions: - #6
    - Computer Crimes - #7
    - AMA and VeriSign - #9
    - MEDePass and VeriSign - #9
    - You Thought It Was Safe (Eli Lilly) - #13
    - VPN's and PC's - #13
    - Smart Cards - #13
    - Disaster Recovery Plans - #13
    - AMA and CMA and VeriSign - #13
    - ComTrust and VeriSign - #13
    - PDA's and the AMA - #14
    - Telecommuting - #14
    - Outsourcing - #14
    - Biometrics - #16
    - Qualified People - #18
    - Risk Assessments - #18
    - Fax - #18
    - Internet - #20
    - Microsoft - #20
    - Web Sites - #20
    - Web Audit - #20
    - Public Health - #20
    - Costs - #20
    - Homeland: The Need for HIPAA - #21
    - Policies and Procedures - #22
    - Biotech - Comdex
    - Security: Information is Critical - #23
    - Federal IT Security - #24
    - Are Your Patches Current? - #25
    - Experience Is In Demand - #25
    - Contingency Planning Guide - #26
    - Firewalls - #26
    - OCTAVE - #26
    - Microsoft - #26
    - Biometrics - #27
    - Smart Cards Biometrics, PKI, FBI - #27
    - Eli Lilly 2 - #27
    - Crack Passwords - #27
    - Survey of Threats - #28
    - Wireless Vulnerabilities - #28
    - Email - #28
    - Firewalls 101 - #28
    - Hospitals Boosting Data Security - #29
    - Intrusion Detection Perspective - #29
    - Intrusion Detection 101 - #29
    - The Legal Risks of Computer Pests - #29
    - Legal: ~ Now - #30
    - Firewall Configuration - #31
    - Instant Messaging - #32
    - Attach Trends - #32
    - Patches - #32
    - ~ in Vendor Contracts - #32
    - Weaknesses That are Known - #33
    - Palm Pilots - #34
    - Beware of New Technology - #35
    - Anatomy of a Hacking - #35
    - Disposal of Computers - #35
    - SAML Specification Ready for Review - #35
    - ~: Expense or Investment? - #36
    - ~: Reducing Insider Attacks - #36
    - ~: CSO and CTO? - #36
    - ~: Tracking Progress - #36
    - ~: Developing Policies - #37
    - ~: Delayed Again - #38
    - ~: Wireless Networks and Devices - #39
    - ~: Wireless Lans - #39
    - ~: Pocket PC's - #39
    - ~: Policing Policies - #39
    - ~: Trends in Viruses - #39
    - ~: NIST guidelines - #42
    - ~: Small Org. Connected to Large Networks - #42
    - ~: Microsoft Word - #42
    - Wireless Secure at Last? - #42
    - ~: Managing Viruses - #42
    - ~: Network Worms - #43
    - ~: Employee Leaves - #44
    - ~: Policies That Work - #45
    - ~: Percent of IT Budget - #45
    - ~: Top 20 Vulnerabilities - #45
    - ~: Passwords - #45
    - ~: Event Management - #45
    - ~: Certification and Accreditation - #45
    - ~: Federal Government - #47
    - Status: ~ Regulations - #49
    - ~: A Broader Base - #49
    - Camera Phones in Locker-Rooms - #49
    - ~: SQL Worm, Internet and Patches - #50
    ~: Master Key Copying Revealed - #50
    - ~: Final Standards #51
    - DWT Analysis & Comments on Security Rules - #52
    - ~ Rules and Litigation - #52
    - ~: Identity Theft - #53
    - ~: Identity Theft 7,000 Patient Files - #53
    - ~: Identity Theft by Medical Assistant - #53
    - ~: HIPAA Law Firm Solicitation - #53
    - ~: Notification in Case of Breech - #53
    - ~: California SB 1386 - #53
    - ~: Payment Processing & Banks - #53
    - ~: Access via Goggle | Duh! - #55
    - ~: Physicians & Data Bases | Duh! - #55
    - ~: Gartner Issues - #55
    - ~: "Events" increase 84% in Three Months - #55
    - SARS Exploitation by Computer Virus - #56
    - ~: Audits - #56
    - ~: Mobile Devices - #56
    - ~: Mobile Devices for EMS - #56
    - ~: SPAM - #56
    - ~: SearchSecurity HIPAA Expert Q&A - #56
    - ~: Getting Started - #57
    - ~: Microsoft - #57

    Security: The Human Side
    - Eli Lilly 2 - #27
    - Anatomy of a Hacking - #35
    - Disposal of Computers - #35
    - Security: People, Processes Supersede Technology - #37

    Smart Cards
    - Security - #13
    - Humana plans
    - Biometrics, PKI & FBI - #27

    Use of Social Security Numbers - #30
    HIPAA and States - #52

    Status:
    - Privacy and Security - #1
    - Gartner - #8
    - Amer. Hospital Assoc. Survey - #10
    - Medicare - #10
    - of Regulations - #21
    - HIMSS Survey: Fall 2001 - #22
    - | Budgets - #22
    - | Use of Consultants - #22
    - | E-Health Strategies - #22
    - | Vendors - #22
    - Proposed Security Rule - Early 2002 - #23
    - Payers Unsure Partners Comply - #23
    - Status: Health Claims Processing - #23
    - Status: Transactions Delayed - #24
    - Status: Transaction Delay Signed - #25
    - Are Your Patches Current? - #25
    - IT Priorities - #27
    - Compliance - #27
    - Vendors and Transactions - #27
    - Pending Regulations - #29
    - HIMSS Vendor Survey - #32
    - Bank Survey - #32
    - Use of email by Physicians - #32
    - California Privacy Implementation Survey - #33
    - HHS Estimated Publication Dates - #34
    - 3 Regulations Published May 31, 2002 - #35
    - Hospitals Slow to Comply - #35
    - Transaction: ~ of Requests for Extensions - #37
    - Privacy and Security Regulations - #37
    - Security: Delayed Again - #38
    - ~ 2nd Final Privacy Rule -#40
    - Status: Transaction Extensions - #41
    - Status: Low Implement. High Confusion - #44
    - Status: Security Regulations - #46
    - Status: Physicians - #46
    - Status: Transaction Extension - #46
    - Status: Fall 2002 Survey - #46
    - HHS Readying More HIPAA Rules - #48
    - ~: Security Regulations - #49
    - Status: Winter HIPAA Survey #51
    - Status: Transactions, WEDI - #56
    - Status: Transactions and States - #56

    Surveys and Certification - #54
    Tablet PCs - Comdex - #22

    Testing
    - Transactions - #8
    - Transaction Test & Cert. - #14
    - Transactions by April 2003 - #24
    - Planning for April 2003 #27

    The Need for HIPAA - #1

    Tools
    - Project Planning & Reporting - #11
    - New Web Page - #13
    - Transaction Test & Cert. - #14
    - COBOL HIPAA Modification - #30
    - Security Management - #30
    - Online Self-Assessment - #30
    - Online Analysis & Documentation - #30
    - HIPAA Compliance ~ Donated - #33

    Topic Papers - collections of articles by topic
    - Privacy
    - Transactions
    - Security

    Training:
    Policies, Procedures and ~ - #10
    - Privacy: ~ - #14
    - Privacy: ~ - #34
    - ~ California - #35
    - Training: Cost and Scope - #53

    Transactions:
    -
    Transactions - #6
    - Management Questions: - #6
    - Scope: Transactions - #6
    - Mapping: The Difficult 10% - #19
    - Mapping: Optional Data - #19
    - Data: Management Questions: - #19
    - Topic Papers - #19
    - Sequencing - #22
    - Status: Delayed to October 23 (Congress) - #24
    - Status: Delay Signed - #25
    - Planning for October 2003 - #26
    - Delays Q&A - #29
    - Testing! Testing! - #29
    - Myths & Realities - #29
    - Filing for Extension - #31
    - ~ and Third Party Testing - #31
    - Privacy & ~ - 32
    - Filing for Extension - #33
    - Permutations - #34
    - Vendors of Direct 837 Services - #37
    - Status of Requests for Extensions - #37
    - Privacy Rule, Transactions, Applicability - #38
    - Project Contingency Planning: ~ - #38
    - Transactions: De-Identification Software - #46
    - ~: Updated Final Rule #51
    - ~: CAQH and WEDI Web Site #51
    - Transactions: Payers Schedules Online - #54
    - Transactions: Access or Post Schedules Online - #54
    - Transactions: Companion Guide - #54
    - Status: Transactions, WEDI - #56
    - Status: Transactions and States - #56



    The Value in HIPAA - #2
    HIPAA Webinar - #38
    What is HIPAA? - #29

    Wireless:
    - PDA's and the AMA - #14
    - Wireless - #16
    - Access to Mobile and Wireless Tools ... - #21
    - X12N Implementation Guides - Addenda - #21
    - Wireless and Mobile Computing - #23
    - Security: ~ Vulnerabilities - #28
    -
    - Wireless Secure at Last? - #42


    HIPAA and Y2K - #5
    HIPAA and Y2K: Analogy - #11
    ___________

    The HIPAA Implementation Newsletter is emailed periodically to subscribers by Lyon, Popanz & Forester. Copyright 2001, All Rights Reserved. Issues are posted on the Web concurrent with email distribution. Edited by Hal Amens To subscribe, click.

    Information is the HIPAA Implementation newsletter is based on our experience as management consultants and sources we consider reliable. It contains neither legal nor financial advice. For that, consult appropriate professionals.

    Lyon, Popanz & Forester is a management-consulting firm that designs and manages projects that solve management problems. Planning, program management offices, and project management for HIPAA are areas of special interest.

    Lyon, Popanz & Forester's home page